Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1685 Disable or Modify Tools |
MalwareNanoCore | NanoCore can modify the victim's anti-virus. |
| T1685 Disable or Modify Tools |
MalwareGold Dragon | Gold Dragon terminates anti-malware processes if they’re found running on the system. |
| T1685 Disable or Modify Tools |
MalwareCarberp | Carberp has attempted to disable security software by creating a suspended process for the security software and injecting code to delete antivirus core files when the process is resumed. |
| T1685 Disable or Modify Tools |
MalwareTinyZBot | TinyZBot can disable Avira anti-virus. |
| T1685 Disable or Modify Tools |
MalwareProton | Proton kills security tools like Wireshark that are running. |
| T1685 Disable or Modify Tools |
MalwareMango | Mango contains an unused capability to block endpoint security solutions from loading user-mode code hooks via a DLL in a specified process by using the `UpdateProcThreadAttribute API` to set the `PROC_THREAD_ATTRIBUTE_MITIGATION_POLICY` to `PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON` for an identified process. |
| T1685 Disable or Modify Tools |
MalwarePHASEJAM | PHASEJAM has modified Ivanti Connect Secure appliances and blocks the system upgrades by altering the DSUpgrade.pm file. |
| T1685 Disable or Modify Tools |
MalwareClop | Clop can uninstall or disable security products. |
| T1685 Disable or Modify Tools |
MalwareEgregor | Egregor has disabled Windows Defender to evade protections. |
| T1685 Disable or Modify Tools |
MalwareStealBit | StealBit can configure processes to not display certain Windows error messages by through use of the `NtSetInformationProcess`. |
| T1685 Disable or Modify Tools |
MalwareZxShell | ZxShell can kill AV products' processes. |
| T1685 Disable or Modify Tools |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has modified the Ivanti Integrity Checker Tool to evade detection. |
| T1685 Disable or Modify Tools |
MalwareEbury | Ebury can disable SELinux Role-Based Access Control and deactivate PAM modules. |
| T1685 Disable or Modify Tools |
MalwareMeteor | Meteor can attempt to uninstall Kaspersky Antivirus or remove the Kaspersky license; it can also add all files and folders related to the attack to the Windows Defender exclusion list. |
| T1685 Disable or Modify Tools |
MalwareZIPLINE | ZIPLINE can add itself to the exclusion list for the Ivanti Connect Secure Integrity Checker Tool if the `--exclude` parameter is passed by the `tar` process. |
| T1685 Disable or Modify Tools |
MalwareMaze | Maze has disabled dynamic analysis and other security tools including IDA debugger, x32dbg, and OllyDbg. It has also disabled Windows Defender's Real-Time Monitoring feature and attempted to disable endpoint protection services. |
| T1685 Disable or Modify Tools |
MalwareChChes | ChChes can alter the victim's proxy configuration. |
| T1685 Disable or Modify Tools |
MalwareShai-Hulud | Shai-Hulud has replaced DNS configuration from `/tmp/resolved.conf` in order to gain control of network-level control within CI environments and has flushed iptables rules using `sudo iptables -F OUTPUT` and `sudo iptables -F DOCKER-USER`. |
| T1685 Disable or Modify Tools |
MalwareJPIN | JPIN can lower security settings by changing Registry keys. |
| T1685 Disable or Modify Tools |
MalwareKOCTOPUS | KOCTOPUS will attempt to delete or disable all Registry keys and scheduled tasks related to Microsoft Security Defender and Security Essentials. |
| T1685 Disable or Modify Tools |
MalwareQilin | Qilin can terminate antivirus-related processes and services. |
| T1685 Disable or Modify Tools |
MalwareLazyWiper | LazyWiper can disable Microsoft Windows Defender Real-Time Monitoring with the `Set-MpPreference` cmdlet. |
| T1685 Disable or Modify Tools |
MalwareAgent Tesla | Agent Tesla has the capability to kill any running analysis processes and AV software. |
| T1685 Disable or Modify Tools |
MalwarePOWERSTATS | POWERSTATS can disable Microsoft Office Protected View by changing Registry keys. |
| T1685 Disable or Modify Tools |
MalwareDRYHOOK | DRYHOOK has killed all instances of the `cgi-server` process in order for the modified Perl module to be activated. |
| T1685 Disable or Modify Tools |
MalwareGoopy | Goopy has the ability to disable Microsoft Outlook's security policies to disable macro warnings. |
| T1685 Disable or Modify Tools |
MalwareQakBot | QakBot has the ability to modify the Registry to add its binaries to the Windows Defender exclusion list. |
| T1685 Disable or Modify Tools |
MalwareSplatCloak | SplatCloak has identified and disabled API callback features of Windows Defender and Kaspersky. |
| T1685 Disable or Modify Tools |
MalwareWaterbear | Waterbear can hook the |
| T1685 Disable or Modify Tools |
MalwareH1N1 | H1N1 kills and disables services for Windows Security Center, and Windows Defender. |
| T1685 Disable or Modify Tools |
MalwareWarzoneRAT | WarzoneRAT can disarm Windows Defender during the UAC process to evade detection. |
| T1685 Disable or Modify Tools |
ToolSILENTTRINITY | SILENTTRINITY's `amsiPatch.py` module can disable Antimalware Scan Interface (AMSI) functions. |
| T1685 Disable or Modify Tools |
ToolDCRAT | DCRAT can patch Microsoft’s Antimalware Scan Interface (AMSI) to evade detection. |
| T1685 Disable or Modify Tools |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to hide memory artifacts and to patch Event Tracing for Windows (ETW) and the Anti Malware Scan Interface (AMSI). |
| T1685 Disable or Modify Tools |
ToolImminent Monitor | Imminent Monitor has a feature to disable Windows Task Manager. |
| T1685 Disable or Modify Tools |
ToolDonut | Donut can patch Antimalware Scan Interface (AMSI), Windows Lockdown Policy (WLDP), as well as exit-related Native API functions to avoid process termination. |
| T1685.001 Disable or Modify Windows Event Log |
ToolWevtutil | Wevtutil can be used to disable specific event logs on the system. |
| T1685.002 Disable or Modify Cloud Log |
ToolPacu | Pacu can disable or otherwise restrict various AWS logging services, such as AWS CloudTrail and VPC flow logs. |
| T1685.003 Modify or Spoof Tool UI |
MalwarePHASEJAM | PHASEJAM has prevented legitimate Ivanti Connect Secure system upgrades by intercepting the upgrade command and rendering fake HTML upgrade progress bar through a function called `processUpgradeDisplay()` which allowed the compromised device to remain under the control of the adversary. |
| T1685.004 Disable or Modify Linux Audit System Log |
MalwareEbury | Ebury disables OpenSSH, system (`systemd`), and audit logs (`/sbin/auditd`) when the backdoor is active. |
| T1685.005 Clear Windows Event Logs |
MalwareSynAck | SynAck clears event logs. |
| T1685.005 Clear Windows Event Logs |
MalwareRansomHub | RansomHub can delete events from the Security, System, and Application logs. |
| T1685.005 Clear Windows Event Logs |
MalwareOlympic Destroyer | Olympic Destroyer will attempt to clear the System and Security event logs using |
| T1685.005 Clear Windows Event Logs |
MalwareDUSTTRAP | DUSTTRAP can delete infected system log information. |
| T1685.005 Clear Windows Event Logs |
MalwareMafalda | Mafalda can delete Windows Event logs by invoking the `OpenEventLogW` and `ClearEventLogW` functions. |
| T1685.005 Clear Windows Event Logs |
MalwareShrinkLocker | ShrinkLocker calls Wevtutil to clear the Windows PowerShell and Microsoft-Windows-Powershell/Operational logs. |
| T1685.005 Clear Windows Event Logs |
MalwareApostle | Apostle will attempt to delete all event logs on a victim machine following file wipe activity. |
| T1685.005 Clear Windows Event Logs |
MalwareBlackCat | BlackCat can clear Windows event logs using `wevtutil.exe`. |
| T1685.005 Clear Windows Event Logs |
MalwareLucifer | Lucifer can clear and remove event logs. |
| T1685.005 Clear Windows Event Logs |
MalwareBlackEnergy | The BlackEnergy component KillDisk is capable of deleting Windows Event Logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.